First published: Wed Mar 15 2023(Updated: )
CVE-2023-28104 DDOS attack on graphql endpoints
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/silverstripe/graphql | >=4.1.1<4.1.2>=4.2.2<4.2.3 | |
Silverstripe Graphql | =4.1.1 | |
Silverstripe Graphql | =4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this DDOS attack on graphql endpoints is CVE-2023-28104.
The software affected by this vulnerability is graphql version 4.1.1 up to 4.1.2 and version 4.2.2 up to 4.2.3 from the composer/silverstripe/graphql package.
The severity of this vulnerability is not provided in the information available.
To fix this vulnerability, it is recommended to update the graphql package to a version that is not affected.
More information about this vulnerability can be found at the following link: https://www.silverstripe.org/download/security-releases/CVE-2023-28104